Find notable cyber news and cases, enriched with sources, timelines, and signals.

KREMLIN browser-extension credential theft activity

Malware Activity
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

The KREMLIN malware operation is using malicious browser extensions and multi-stage loaders to steal credentials and session tokens from Chrome and Edge users, increasing the risk of account takeover and browser-data theft. The activity has been active since at least May 2025 and is tied to a broader toolkit-delivery chain that includes loaders and installers. It also uses infrastructure-hiding and evasion techniques to sustain access and reduce disruption. The scope reaches at least 1,515 infected systems, most of them in Brazil.

Related Happenings

REF9334 Brazilian bank lure campaign using malicious browser extensions

Campaign
H score51 First: 15.09.2026 21:54 Last: 15.09.2026 21:54 Sources 1

How related: "Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge."

About this happening: The REF9334 campaign is actively using Brazilian bank lures to deploy a malicious browser extension, putting Chrome and Edge users at risk of credential theft....

Malicious Chrome and Edge browser-extension campaign

Campaign
H score16 First: 30.08.2026 17:17 Last: 30.08.2026 17:17 Sources 1

About this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

Atlas RAT and related loaders deployed for remote access and credential theft

Malware Activity
H score33 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

About this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...

Torg Grabber browser-extension theft activity

Malware Activity
H score36 First: 25.03.2026 20:32 Last: 25.03.2026 20:32 Sources 1

About this happening: The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...

Timeline

  1. 15.09.2026 21:54 1 articles · 2h ago

    KREMLIN moves endpoint rotation to Ethereum smart contracts

    Technical Analysis Update

    On May 19, 2026, KREMLIN shifted to Ethereum smart contracts to resolve volmira[.]site and zaviro[.]online, allowing the operation to rotate command-and-control endpoints and payload-hosting locations while also retrieving the AVSync System Inc. browser extension version 1.0.0 and ID ndpbidppejfanjbhfgjlohfanbfbklff.

    Show sources
  2. 15.09.2026 21:54 2 articles · 2h ago

    Elastic Security Labs discloses REF9334 banking malware

    Initial Disclosure

    On September 15, 2026, Elastic Security Labs disclosed REF9334, a previously undocumented Brazilian banking malware operation active since at least May 2025 that uses lures impersonating Brazilian banks to install a malicious browser extension on Google Chrome and Microsoft Edge and steal credentials, session tokens, and sensitive data.

    Show sources